Asp.net ºǫ́µ÷ÓÃjs·½·¨(ת)
1. ÓÃResponse.Write·½·¨
¡¡¡¡´úÂëÈçÏ£º
Response.Write("<script type='text/javascript'>alert("XXX");</script>");
´Ë·½·¨È±ÏݾÍÊDz»Äܵ÷Óýű¾ÎļþÖеÄ×Ô¶¨ÒåµÄº¯Êý£¬Ö»Äܵ÷ÓÃÄÚ²¿º¯Êý£¬¾ßÌåµ÷ÓÃ×Ô¶¨ÒåµÄº¯ÊýÖ»ÄÜÔÚResponse.WriteдÉϺ¯Êý¶¨ Ò壬±ÈÈç
Response.Write("<script type='text/javascript'>function myfun(){}</script>");
2.ÓÃClientScriptÀà
¡¡¡¡´úÂëÈçÏ£ºÔÚÏëµ÷ÓÃij¸öjavascript½Å±¾º¯ÊýµÄµØ·½Ìí¼Ó´úÂ룬עÒâÒª±£Ö¤MyFunÒѾÔڽű¾ÎļþÖж¨Òå¹ýÁË¡£
ClientScript.RegisterStartupScript(ClientScript.GetType(), "myscript", "<script>MyFun();</script>");
¡¡¡¡Õâ¸ö·½·¨±ÈResponse.Write¸ü·½±ãһЩ£¬¿ÉÒÔÖ±½Óµ÷Óýű¾ÎļþÖеÄ×Ô¶¨Ò庯Êý¡£
3.ÆÕͨµÄÌí¼Ó¿Ø¼þµÄAttributesÊôÐÔ
¡¡¡¡¶ÔÓÚÆÕͨ°´Å¥¾ÍÊÇ£ºButton1.Attributes.Add("onclick","MyFun();");
¡¡¡¡Ö»ÄÜÔÚOnloadÖлòÀàËÆÓÚonloadµÄ³õʼ»¯¹ý³ÌÖÐÌí¼Ó²ÅÓÐЧ¡£¶øÇÒÊÇÏÈÖ´Ðнű¾º¯Êý£¬ÎÞ·¨¸Ä±äÖ´ÐÐ˳Ðò¡£
×¢Ò⣬ÒÔÉÏËùÓз½·¨ÖУ¬ºǫ́´úÂë¶¼²»ÄÜÓÐת»¯µ±Ç°Ò³µÄ´úÂ룬±ÈÈçRedirectµÈ£¬Òª°Ñתҳ´úÂë·ÅÔڽű¾ÀïÃæ
Ïà¹ØÎĵµ£º
ÑÝÁ·£ºÊ¹Óà XCOPY ²¿Êð ASP.NET Web Ó¦ÓóÌÐò
²¿Êð ASP.NET Ó¦ÓóÌÐò·Ç³£¼òµ¥¡£ÄúÐèÒª½«Ëù´´½¨µÄÓ¦ÓóÌÐòÎļþ´Ó¿ª·¢¼ÆËã»ú¸´ÖƵ½½«³ÐÔØÓ¦ÓóÌÐòµÄ³ÉÆ· Web ·þÎñÆ÷¡£¿ÉÒÔʹÓà XCOPY ÃüÁîÐй¤¾ß»òϲ»¶µÄ FTP Ó¦ÓóÌÐò£¬½«Îļþ´ÓÒ»¸öλÖø´ÖƵ½ÁíÒ»¸öλÖá£Óйس£¹æ²¿ÊðµÄ¸ü¶àÐÅÏ¢£¬Çë²Î¼û .NET Framework ²¿Êð»ù´¡¡£
×¢Òâ
......
ʹÓà SqlDataSource ¿Ø¼þÖ»ÐèºÜÉٵĴúÂë»òÎÞÐèÈκδúÂë¼´¿É´ÓÊý¾Ý¿âÖмìË÷Êý¾Ý¡£SqlDataSource ¿Ø¼þ¿ÉÓÃÓÚÈκξßÓйØÁª ADO.NET Ìṩ³ÌÐò£¨ÔÚÅäÖÃÎļþµÄ DbProviderFactories ½ÚÖÐÅäÖ㩵ÄÊý¾Ý¿â£¬°üÀ¨ Microsoft SQL Server¡¢Oracle¡¢ODBC »ò OLE DB Êý¾Ý¿â£¨Èç Microsoft Access£©¡£ÄúÔÚÅäÖÃʱָ¶¨ SqlDataSource ʹÓõ ......
Ò»°ã´î½¨Èý²ã¿ò¼ÜÏîÄ¿ÊÇÕâÑùµÄ:
1¡¢´´½¨Ò»¸ö¿ÕµÄ½â¾ö·½°¸
2¡¢´´½¨Àà¿âÏîÄ¿
3¡¢´´½¨ÍøÕ¾ÏîÄ¿
4¡¢Ìí¼ÓÏîĿ֮¼äµÄÒýÓã¬ÐèҪעÒâµÄÊDZíʾ²ã£¨ÍøÕ¾ÏîÄ¿²ã£©ÊDz»ÐèÒªÌí¼ÓÆäËü²ãÒýÓõģ¬ÒòΪÔËÐк󣬻á×Ô¶¯²úÉú¶ÔÆäËüÏîÄ¿µÄÒýÓÃ
Èý²ã½á¹¹£º
Êý¾Ý·ÃÎʲ㣺Ö÷ҪʵÏÖÊý ......
¿ÉÒÔʹÓà SqlDataSource ¿Ø¼þÐÞ¸ÄÊý¾Ý¿âÖеÄÊý¾Ý¡£Ê¹Óøüз½°¸ÖÐµÄ SqlDataSource ¿Ø¼þµÄ×î³£Ó÷½·¨ÊǼìË÷Êý¾Ý²¢Ê¹ÓÃÊý¾Ý°ó¶¨ Web ·þÎñÆ÷¿Ø¼þ£¨Èç GridView¡¢DetailsView »ò FormView ¿Ø¼þ£©ÏÔʾÊý¾Ý¡£¿ÉÒÔÅäÖÃÊý¾Ý°ó¶¨¿Ø¼þºÍ SqlDataSource ÒÔ¸üÐÂÊý¾Ý¡£´ó¶àÊýÊý¾Ý°ó¶¨¿Ø¼þ¶¼ÔÊÐíÄú½«Æä ......
ͨ¹ýAsp.net(C#)Ó¦ÓóÌÐò¶ÁÈ¡±¾µØÉÏ´«µÄExcleÎļþ,´æ·Åµ½DataSetÖÐ,ͨ¹ýDataSetÖеķ½·¨Ö±½ÓÉú³ÉXMLÎļþ.
C# Code
if (this.FileUpload1.PostedFile != null)
{
string filename = this.FileUpl ......